Devices & Services Vulnerability Reporting

Who are we?

The Devices & Services Security team is responsible for managing vulnerabilities discovered in Google products (Pixel, Nest, Home & Fitbit) and many of the core services and apps bundled with these devices.

Reporting Vulnerabilities

Any developer, device user, or security researcher can notify the Devices & Services Security team of potential security issues through our vulnerability reporting form that is part of the Google Devices Security Reward Program. Bugs marked as security issues aren't externally visible, but they may eventually be made visible after the issue is evaluated or resolved. For country-specific vulnerability reporting details (including for the UK and Australia), please refer to the dedicated regional sections below.

Australian Cyber Security (Security Standards for Smart Device) Rules 2025 (“Cyber Rules”)

The Cyber Rules is an Australian law that sets out certain cybersecurity requirements for smart devices.
You can find the individual Statements of Compliance for our devices here:

Reporting Security Issues
Any user in Australia can notify the Devices & Services Security team of potential security issues or vulnerabilities through our vulnerability reporting form. Upon receipt of your message, we will send an automated reply that includes a tracking identifier for your reference. More information, such as how to track your report's progress, can be found in the Bughunter FAQ section.

UK Product Security Telecommunications Infrastructure Regulations 2023 (“PSTI Regulations”)

The PSTI Regulations is a UK law that sets out certain cybersecurity requirements for devices that connect to the internet.
You can find the individual Statements of Compliance for our devices here:

Reporting Security Issues
Any user in the UK can notify the Devices & Services Security team of potential security issues or vulnerabilities through our vulnerability reporting form. Upon receipt of your message, we will send an automated reply that includes a tracking identifier for your reference. More information, such as how to track your report's progress, can be found in the Bughunter FAQ section.

Triaging Bugs

The first task in handling a security vulnerability is to identify the severity of the bug and which component of the device is affected. The severity level determines how the issue is prioritized, and the component determines who fixes the bug, who is notified, and how the fix gets deployed to users.

Vulnerability Disclosures

For software apps and services associated with our devices, we follow Google’s  vulnerability disclosure deadline. For device and system software components, some vulnerabilities may require longer remediation and disclosure timelines (e.g., due to dependencies with components delivered by Silicon vendors).

true
Search
Clear search
Close search
Google apps
Main menu
10044595847845523345
true
Search Help Center
false
true
true
true
false
false
false
false
false